2.1
CVSSv2

CVE-2014-1858

Published: 08/01/2018 Updated: 30/01/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

__init__.py in f2py in NumPy prior to 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

numpy numpy

Vendor Advisories

Debian Bug report logs - #737778 python-numpy: insecure use of /tmp (CVE-2014-1858 CVE-2014-1859) Package: python-numpy; Maintainer for python-numpy is Sandro Tosi <morph@debianorg>; Source for python-numpy is src:python-numpy (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: Wed, 5 Feb 2014 21 ...
f2py insecurely uses a temporary file A local attacker could use this flaw to perform a symbolic link attack to modify an arbitrary file accessible to the user running f2py ...
__init__py in f2py in NumPy before 181 allows local users to write to arbitrary files via a symlink attack on a temporary file ...